IP Library Granted Patent US 12,259,970
Granted Patent B1
US 12,259,970 · App. 17/656,042 · Granted Mar 25, 2025

Systems and methods for identifying security threats in smart contract-based services to protect against malicious attacks utilizing off-blockchain resources

Inventors: David Luz Silva (Dublin, IE); Iskander Sanchez Rola (Antibes, FR)
Assignee: GEN DIGITAL INC.
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,259,970
App. No.
17/656,042
Granted
Mar 25, 2025
Kind
B1
Abstract

The disclosed computer-implemented method for identifying security threats in smart contract-based services to protect against malicious attacks utilizing off-blockchain resources may include (i) identifying a reference associated with a transaction on a smart contract-based platform, (ii) detecting content describing one or more smart contracts associated with the reference on the platform, (iii) extracting an identifier from the content to locate off-blockchain resources utilized by the smart contracts, (iv) determining potential security threats associated with the off-blockchain resources, and (v) performing a security action that protects against the potential security threats. Various other methods, systems, and computer-readable media are also disclosed.

Claims (62)

1. A computer-implemented method for identifying security threats in smart contract-based services to protect against malicious attacks utilizing off-blockchain resources, at least a portion of the method being performed by one or more computing devices comprising at least one processor, the method comprising:

identifying a reference associated with a transaction on a smart contract-based platform;

detecting, by the one or more computing devices, smart contract source code corresponding to one or more smart contracts associated with the reference on the platform;

extracting, by the one or more computing devices, an identifier from the smart contract source code to locate off-blockchain resources utilized by a smart contract oracle included in the smart contract source code by:

parsing the smart contract source code to identify an address utilized by the smart contract oracle to contact a domain associated with the off-blockchain resources;

mapping the address to a domain contacted by the smart contract oracle; and

extracting the domain;

determining, by the one or more computing devices, potential security threats associated with the off-blockchain resources; and

performing, by the one or more computing devices, a security action that protects against the potential security threats.

2. The computer-implemented method of claim 1 , wherein identifying the reference associated with the transaction on the smart contract-based platform comprises:

detecting a blockchain transaction on the platform;

identifying a transaction destination associated with the blockchain transaction; and

resolving the transaction destination into a blockchain address.

3. The computer-implemented method of claim 1 , wherein detecting the smart contract source code corresponding to the one or more smart contracts associated with the reference on the platform comprises identifying the smart contract source code associated with the reference on the platform.

4. The computer-implemented method of claim 1 , wherein extracting, from the smart contract source code, the identifier to locate the off-blockchain resources utilized by the smart contract oracle comprises:

parsing the smart contract source code to identify a domain associated with the off-blockchain resources that is contacted by the smart contracts; and

extracting the domain.

5. The computer-implemented method of claim 1 , wherein determining the potential security threats associated with the off-blockchain resources comprises performing an evaluation to identify the potential security threats based on at least one domain associated with the off-blockchain resources.

6. The computer-implemented method of claim 5 , wherein performing the evaluation to identify the potential security threats based on the at least one domain associated with the off-blockchain resources comprises evaluating one or more of:

a reputation database for historical data associated with the domain;

a web stack for implementing a website associated with the domain to identify at least one of previously known security vulnerabilities and data leakages;

certificate registration data associated with the domain; or

a domain name registry service to access domain name registration data for the domain.

7. The computer-implemented method of claim 6 , further comprising calculating a risk score based on the evaluation.

8. The computer-implemented method of claim 1 , wherein performing the security action comprises generating a notification identifying the potential security threats associated with the off-blockchain resources.

9. The computer-implemented method of claim 8 , wherein the notification comprises a risk assessment based on one or more security vulnerabilities determined for an off-blockchain resource domain utilized by the smart contracts.

10. A system for identifying security threats in smart contract-based services to protect against malicious attacks utilizing off-blockchain resources, the system comprising:

at least one physical processor;

physical memory comprising computer-executable instructions and one or more modules that, when executed by the physical processor, cause the physical processor to:

identify, by an identification module, a reference associated with a transaction on a smart contract-based platform;

detect, by a detection module, smart contract source code corresponding to one or more smart contracts associated with the reference on the platform;

extract, by an extraction module, an identifier from the smart contract source code to locate off-blockchain resources utilized by a smart contract oracle included in the smart contract source code by:

parsing the smart contract source code to identify an address utilized by the smart contract oracle to contact a domain associated with the off-blockchain resources;

mapping the address to a domain contacted by the smart contract oracle; and

extracting the domain;

determine, by a determining module, potential security threats associated with the off-blockchain resources; and

perform, by a security module, a security action that protects against the potential security threats.

11. The system of claim 10 , wherein the identification module identifies the reference associated with the transaction on the smart contract-based platform by:

detecting a blockchain transaction on the platform;

identifying a transaction destination associated with the blockchain transaction; and

resolving the transaction destination into a blockchain address.

12. The system of claim 10 , wherein the detection module detects the smart contract source code corresponding to the one or more smart contracts associated with the reference on the platform by identifying the smart contract source code associated with the reference on the platform.

13. The system of claim 10 , wherein the extraction module extracts the identifier from the smart contract source code to locate the off-blockchain resources utilized by the smart contract oracle by:

parsing the smart contract source code to identify a domain associated with the off-blockchain resources that is contacted by the smart contracts; and

extracting the domain.

14. The system of claim 10 , wherein the determining module determines the potential security threats associated with the off-blockchain resources comprises by performing an evaluation to identify the potential security threats based on at least one domain associated with the off-blockchain resources.

15. The system of claim 14 , wherein the determining module performs the evaluation to identify the potential security threats based on the at least one domain associated with the off-blockchain resources by evaluating one or more of:

a reputation database for historical data associated with the domain;

a web stack for implementing a website associated with the domain to identify at least one of previously known security vulnerabilities and data leakages;

certificate registration data associated with the domain; or

a domain name registry service to access domain name registration data for the domain.

16. The system of claim 15 , wherein the determining module further performs the evaluation to identify the potential security threats based on the at least one domain associated with the off-blockchain resources by calculating a risk score.

17. The system of claim 10 , wherein the security module performs the security action by generating a notification identifying the potential security threats associated with the off-blockchain resources.

18. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

identify a reference associated with a transaction on a smart contract-based platform;

detect smart contract source code corresponding to one or more smart contracts associated with the reference on the platform;

extract an identifier from the smart contract source code to locate off-blockchain resources utilized by a smart contract oracle included in the smart contract source code by:

parsing the smart contract source code to identify an address utilized by the smart contract oracle to contact a domain associated with the off-blockchain resources;

mapping the address to a domain contacted by the smart contract oracle; and

extracting the domain;

determine potential security threats associated with the off-blockchain resources; and

perform a security action that protects against the potential security threats.

Assignments (2)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2022
From: SILVA, DAVID LUZ; SANCHEZ ROLA, ISKANDER
To: NORTONLIFELOCK INC.
Reel/Frame 059421/0331 →
References Cited (33)
US 10797860B1 · Dennis · 2020 [cited by examiner]
US 11645650B1 · Singh · 2023 [cited by examiner]
US 20190273739A1 · Pemmaraju · 2019 [cited by examiner]
US 20200050768A1 · Ragnoli · 2020 [cited by examiner]
US 20200082359A1 · Xu · 2020 [cited by examiner]
US 20200177372A1 · Bhamidipati · 2020 [cited by examiner]
US 20200201838A1 · Ciocarlie · 2020 [cited by examiner]
US 20200372154A1 · Bacher · 2020 [cited by examiner]
US 20210014065A1 · Gourisetti · 2021 [cited by examiner]
US 20210037055A1 · Dumont · 2021 [cited by examiner]
US 20210049281A1 · Braghin · 2021 [cited by examiner]
US 20210067339A1 · Schiatti · 2021 [cited by examiner]
US 20210110047A1 · Fang · 2021 [cited by examiner]
US 20210304311A1 · Banescu · 2021 [cited by examiner]
US 20210334363A1 · Kim · 2021 [cited by examiner]
US 20210352139A1 · Madisetti · 2021 [cited by examiner]
US 20210365555A1 · Nissan · 2021 [cited by examiner]
US 20220050887A1 · Han · 2022 [cited by examiner]
US 20220253813A1 · Pospieszalski · 2022 [cited by examiner]
US 20220309491A1 · Shapiro · 2022 [cited by examiner]
US 20230065259A1 · Chen · 2023 [cited by examiner]
CN 108874802A · 2018 [cited by examiner]
CN 113919841A · 2022 [cited by examiner]
CN 111429145B · 2022 [cited by examiner]
CN 113190330B · 2022 [cited by examiner]
Praitheeshan et al., “Security Analysis Methods on Ethereum Smart Contract Vulnerabilities—A Survey”, URL: https://arxiv.org/pdf/1908.08605.pdf, Sep. 16, 2020, pp. 1-21. [cited by applicant]
Samreen et al., “A Survey of Security Vulnerabilities in Ethereum Smart Contracts”, URL: https://arxiv.org/pdf/2105.06974.pdf, Nov. 10-13, 2020, pp. 1-10. [cited by applicant]
Eskandari et al., “SoK: Oracles from the Ground Truth to Market Manipulation”, URL: https://arxiv.org/pdf/2106.00667.pdf, Sep. 26-28, 2021, 14 pages. [cited by applicant]
Tjiam et al., “Your Smart Contracts Are Not Secure: Investigating Arbitrageurs and Oracle Manipulators in Ethereum”, Paper Session 2, CYSARM, Virtual Event, Nov. 19, 2021, pp. 25-35. [cited by applicant]
Breidenbach et al., “Chainlink 2.0: Next Steps in the Evolution of Decentralized Oracle Networks”, URL: https://research.chain.link/whitepaper-v2.pdf, Apr. 15, 2021, pp. 1-136. [cited by applicant]
“ETH PayNow Button”, URL: https://medium.com/@enslisting.com/eth-paynow-button-996405998c8b, Nov. 25, 2017, 12 pages. [cited by applicant]
“How to create your own Oracle with an Ethereum smart contract”, URL: https://www.quicknode.com/guides/solidity/how-to-create-your-own-oracle-with-an-ethereum-smart-contract, Dec. 27, 2021, 5 pages. [cited by applicant]
“What is an Ethereum Address”, URL: https://info.etherscan.com/what-is-an-ethereum-address/, Etherscan, retreived on Apr. 8, 2022, 3 pages. [cited by applicant]